Adding a new SAML identity provider
First you need to create a new SAML application in Google Admin (requires admin privileges in your Google Workspace account).
- Open https://admin.google.com/
- Navigate to Apps, then openWeb and mobile Apps
- Click Add app - Add custom SAML app
- Follow the Google Admin instructions on screen until you get the option to download the IdP metadata. Download this file to you computer, and upload it using Option 1 on this page.
- Review the settings on this page to make sure it looks correct.
If things look good, click Save. - Copy and paste the ACS URL and the Entity ID from the popup dialog into the Google Admin page and use defaults for the remaining items in the wizard.
- Adjust the User Access part of the SAML configuration in the Google Admin page.
By default it is set to Off for everyone.